Feeds

Android antivirus apps CAN'T kill nasties on sight like normal AV - and that's Google's fault

Bad news if you're not a tech-savvy fandroid

Securing Web Applications Made Simple and Scalable

Android users expecting Windows levels of performance from Android-specific antivirus packages are likely to be disappointed because only Google can automatically delete dodgy apps on Android devices, say malware experts.

Anti-malware bods agree that antivirus programs on Android can’t remove viruses automatically, meaning that the process needs to be carried out manually by the user in each and every case.

"Android antimalware applications can block URLs, scan downloads and identify malware that the user may have installed, but they cannot remove malicious applications that are installed by the user," explained Simon Edwards, technical director at Dennis Technology Labs, an experienced antivirus tester and chairman of the Anti-Malware Testing Standards Organization.

"They have to alert the user and hope that the user is able to uninstall them manually, using the usual Android uninstall routine."

Andreas Marx, chief exec of AV-Test, confirmed Edwards' prognosis that Android security applications could only warn about maliciously installed apps, rather than shunting them into quarantine (the norm for equivalent Windows security software).

"The mobile security apps are all running in a sandbox, just like any other app," Marx told El Reg. "Therefore, they are not able to remove malicious apps at their own."

Chocolate factory controls Google malware 'kill switch'

This existing but under-reported behaviour is not inherent to the architecture of Android smartphones and tablets.

Edwards told El Reg: "There actually is a way to remove malware from infected devices automatically. Google has a kill switch that can do it. But only Google has that power currently."

Marx confirmed: "Only Google has the power to use it [the 'kill switch'], as far as we know, but in past they only focused on disabling malicious apps which made it into the Google Play store. It looks like that they don't really care about any third party marketplaces, but leave this field to the AV [antivirus] companies."

We invited Google to explain the design rationale for this treatment of malicious apps on Android devices but are yet to hear back from them.

Security apps on rooted devices might be able to get around these restrictions. However Marx reckons the security drawbacks outweigh this modest advantage.

"If you have a rooted device, some anti-malware apps offer additional features, but rooted devices usually have other kind of security issues, therefore we wouldn't recommend this step," he explained.

Marx reckoned the warning feature of Android anti-malware scanners meets the practical needs of consumers and enterprise users.

"Besides this, the majority of security apps offer to run an on-demand scan from time to time to check for other potential harmful stuff on your device. The security app can warn you, so you can uninstall the potential malicious app later," Marx said, adding that "however, the on-installation check is the most important anti-malware feature."

Scores on the doors

The effectiveness of on-demand and on-access detection of malware by Android antivirus scanners were the main two areas covered by in tests by AV-Test, published last week.

AV-Test put 28 Android security apps through their paces, discovering improved results from previous comparable exercises. Only two products (Zoner Mobile Security and SPAMFighter VirusFighter Android) failed in AV-Test's latest real-world review against 2,124 malicious apps. All the paid-for products from mainstream vendors (Kaspersky, Trend. McAfee, Sophos, etc.) passed, as did freebie scanners from Avast and others.

The malware protection rate during tests run in November and December 2013 was in the range of 42.3 per cent to 100 per cent, with an average detection of 96.6 per cent (6 percentage points better than the testing house's last Android security software review, which was put together in October). Only a few programs created false positives on AV-Test's test systems during the latest review.

An overview of the results can be found here.

The German testing house found that the main difference between free and paid-for Android security apps came from the features they offered rather than in detection of malign apps. Premium security features included functions such as anti-theft, backup and encryption.

The favourable results are welcome given that Android malware is becoming a growing nuisance. In total, AV-Test has already registered more than 1.5 million Android-related malware samples in 2013, and we have more than 1.8 million total in its database. During November 2013, for example, AV-Test was receiving about 6,000 additional unique samples per day. ®

The smart choice: opportunity from uncertainty

More from The Register

next story
BMW's ConnectedDrive falls over, bosses blame upgrade snafu
Traffic flows up 20% as motorway middle lanes miraculously unclog
Putin: Crack Tor for me and I'll make you a MILLIONAIRE
Russian Interior Ministry offers big pile o' roubles for busting pro-privacy browser
Mozilla fixes CRITICAL security holes in Firefox, urges v31 upgrade
Misc memory hazards 'could be exploited' - and guess what, one's a Javascript vuln
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
How long is too long to wait for a security fix?
Synology finally patches OpenSSL bugs in Trevor's NAS
Don't look, Snowden: Security biz chases Tails with zero-day flaws alert
Exodus vows not to sell secrets of whistleblower's favorite OS
Roll out the welcome mat to hackers and crackers
Security chap pens guide to bug bounty programs that won't fail like Yahoo!'s
prev story

Whitepapers

Top three mobile application threats
Prevent sensitive data leakage over insecure channels or stolen mobile devices.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Build a business case: developing custom apps
Learn how to maximize the value of custom applications by accelerating and simplifying their development.